Description
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later
Problem types
Product status
1.8.x before 1.8.51
1.9.x before 1.9.51
Credits
Milan Solanki (LeoSecurity)
References
www.qnap.com/en/security-advisory/qsa-25-27